Reporting & Branding

How to build a board risk report on Mac

Build it in RiskOS, a risk register for macOS. One snapshot, the sections a board actually reads, and a PDF that comes out the same way every quarter.

A board gives risk ten minutes, sometimes fifteen. Almost all of it goes on two questions: what is the worst thing on the list, and is anyone doing something about it. A report that answers both on the first page earns the rest of its length. One that opens with a forty-row table spends its ten minutes on page one, and the conversation never reaches the risks that needed a decision.

Note

Every section of a report is built from one snapshot of your register taken at the moment you export, so the matrix, the top risks and the summary always agree with each other.

Where the report builder lives

Choose Reports in the sidebar. The builder fills the window in three parts: the cover fields at the top — report title, organisation, prepared by — then a list of section toggles, one for each block the report can carry, then scope, which decides whether closed and accepted risks are included at all. The export controls finish the page.

Nothing is produced until you ask for it, and a section switched off is absent from every output rather than hidden in one, because all four are built from the same snapshot. That is worth knowing before you start, because a board report in RiskOS is mostly an exercise in leaving things out.

Build a board report, step by step

  1. Open the Reports section

    Choose Reports in the sidebar, and do it after the register is up to date rather than before. The report takes the register as it stands, so a risk you re-score in five minutes' time will not appear in a file you export now.

  2. Fill in the cover fields

    Give the report a title the board will recognise on an agenda: Risk Report, Q3 2026 reads better than Risk Register. Use the organisation's full legal name, since this is a document that may be minuted. Your own name goes in prepared by, so the person who assembled the figures is on the record beside them.

  3. Switch on the executive summary

    This is the section the board reads, and for some members the only one. It opens the report with the shape of the register at the moment of export: how many risks are active, where they sit on average, how many stand above appetite, how many are overdue for review. Twelve active risks averaging 9.6 out of 25, four of them above an appetite of 9, is a paragraph a chair can hold in their head.

  4. Add the risk matrix

    Switch on the risk matrix. It is the one picture in the report and it does a job no table does, showing the whole register at once so that a cluster in the top-right corner lands before anybody has read a risk title. Place it after the summary, where it frames everything that follows.

  5. Set how many top risks to carry

    Switch on top risks and set the count. The section takes anything from 3 to 50, which covers a one-page note as comfortably as a full principal-risk schedule. For a board pack, five to ten is the working range. Above ten it stops being a shortlist and becomes the register again.

  6. Add controls and open actions

    Switch on open actions. This is the half of the report that answers the second board question: who is doing what, by when, and what is already late. Sixteen open actions of which three are overdue is a sentence that changes a discussion. Add controls as well if your board asks what the organisation relies on, not only what it is exposed to.

  7. Decide what travels as an appendix

    The full register and the per-risk detail pages are appendix material. Switch the full register on when the pack goes out in advance and somebody will want to check a row; switch per-risk detail pages on only when a committee reads a page per risk. Under scope, leave closed and accepted risks out unless the board asked to see what was retired.

  8. Choose Set Up Branding and fill in the business name, tagline, address, phone, email, website and the registration or VAT line, then drop in your logo. The live preview shows the real header and footer, and what it shows is exactly what exports and prints.

  9. Export the PDF

    Press P and choose where the file goes; somewhere like Documents ▸ RiskOS keeps each quarter's pack together. RiskOS confirms the export with the filename when it finishes. Open the file before you circulate it, and read the first two pages the way a director would, at speed.

What each section carries

Ten sections can be switched on and a board report needs about five. The rest exist for the audit committee and the auditor, who want depth rather than shape. Deciding which is which, once, is most of the work of a good report.

The report sections in RiskOS and where each one belongs
SectionWhat it carriesWhere it belongs
Executive summaryThe state of the register at the moment of exportBoard — page one
Risk matrixThe whole register as one gridBoard — page two
Top risksThe worst 3 to 50 rows, worst firstBoard — the discussion
Open actionsWhat is being done, by whom, and what is lateBoard — the decisions
Risk indicatorsMeasured numbers against their thresholdsBoard if they are asked for
Risk eventsRisks that actually happened, and the lessonsBoard after a bad quarter
ControlsWhat the organisation relies on, and how strong it isCommittee
Framework coverageRequirements covered, mapped but not operating, not mappedCommittee and auditor
Full registerEvery active risk as a tableAppendix
Per-risk detail pagesA page for each risk, with its assessment and planAppendix, sparingly

The sections boards ask for by name

Two optional sections come up again and again once a board has seen them. Risk indicators turn the report from a set of opinions into a set of measurements: a restore test success rate of 72 % against a threshold you set yourself is not a judgement anyone needs to debate. Risk events work the other way, since a risk that has already happened twice is no longer hypothetical.

Framework coverage and the audit committee

Framework coverage suits the committee pack rather than the board pack, but it answers the assurance question most directly. It reports three honest states rather than a flattering percentage: covered, where a mapped control is implemented or operating; mapped but not operating; and not mapped. Seven of twenty-eight on the RiskOS Control Baseline is a figure a committee can work with, because it says what the other twenty-one are.

A running order a board can follow

The order is not a matter of taste. A board reads top to bottom under time pressure, and each page should answer the question the one before it raised. Shape first, then severity, then action.

Lead with the shape of the register

The summary and the matrix take about ninety seconds together, and they set every expectation that follows. If four risks sit above appetite, the board knows four conversations are coming and can pace itself. If the top-right corner of the matrix is empty, the meeting can move on.

Then the risks that need a decision

Top risks carries the meeting. Sorted worst first, it puts a row like RSK-0007, Backup restoration has never been tested end to end, at the head of the page with a residual of 15 against a target of 4: a gap of eleven points, with an owner's name beside it. RiskOS generates the list rather than asking you to write it, so it cannot quietly become last quarter's.

Close with what changes before the next meeting

Open actions should be the last thing the board reads, because it is the only section describing the future. Grouped by due state, it shows what is overdue, what is due soon and what is scheduled for later, each row carrying its owner and its parent risk. A board that leaves knowing three actions are late has something it can act on.

Choosing the output for the audience

All four outputs come from the same snapshot, so they never disagree. They differ in what the recipient can do with them, which usually settles the choice.

The four report outputs and when each one suits a board audience
OutputShortcutWhen it suits a board
PDF⇧⌘PThe pack itself. Paginated A4, a branded cover, a running header and footer, and rows that never split across a page.
HTML⇧⌘EOne self-contained file with no scripts and nothing loaded from the internet. For a director who reads on screen.
ExcelSeven sheets whose formulas re-score themselves when a likelihood changes. For the director who tests a what-if.
Print⌘PExactly the PDF, sent to the printer, for meetings held on paper.

In practice the board gets the PDF, and the workbook goes to the one person who always asks what happens if the likelihood on the top risk moves a point. Sending both costs nothing, since they are the same snapshot and cannot drift apart.

Branding, and who the report is for

The cover says whose document this is, and it is the part people look at twice. The branding designer in RiskOS holds your business name, tagline, address, phone, email, website and a registration or VAT line, with a logo in PNG, JPEG, PDF or SVG and an optional variant for dark backgrounds.

If you report to more than one organisation, a group board and a subsidiary or several clients, profiles keep them separate. A profile dresses RiskOS for one organisation: its own methodology, its own appetite, its own report defaults, client name and client logo. Exports then carry that client's prepared-for name and logo while your own identity stays primary, and switching takes a keystroke.

Troubleshooting

The report runs to sixty pages and nobody will read it

Per-risk detail pages are almost always the cause, since they add a page for every risk in scope. Switch them off, bring the top risks count down to about eight, and keep the full register only if the pack goes out in advance. Eight to twelve pages is a normal board report.

The numbers changed after I sent the report

The export is a snapshot of the register at the moment you made it, which is what makes a figure quotable in minutes. If somebody re-scored a risk afterwards, the register moved on and the file did not. Export again once the register has settled, and note the date when you circulate it.

A risk I expected to see is not in the report

Check two things. Closed and accepted risks are left out unless you include them under scope, so a risk the board accepted last quarter will not appear by default. And top risks carries only the number you set, worst first, so a risk ranked eleventh is absent from a list of ten though it is still active.

The logo looks wrong on the cover

Open Set Up Branding and watch the preview rather than guessing, since the preview is the real header and footer. If the mark disappears against a dark cover, add the dark-background variant, a separate slot beside the main logo.

A table row is broken across two pages

It should not be. In the PDF, table headers repeat on every page and rows never split across a page break. If a table still looks wrong, check that you are reading the file from this export rather than an earlier version saved beside it.

A routine for every board cycle

The second board report takes a fraction of the time the first one did, provided the register is kept in shape between meetings rather than rebuilt the week before.

  • Run a review pass first. Walk the risks that are overdue or above appetite in Review before you export, so the report carries current judgements rather than last quarter's.
  • Clear the overdue actions you can. Ten minutes in Actions updating statuses removes the most avoidable question in the meeting.
  • Keep the section toggles steady. A board learns the shape of your report, and changing which sections appear each quarter costs it the familiarity that makes the pack quick to read.
  • Keep the top risks count fixed. If it is ten every quarter, movement in and out of the list becomes information in itself.
  • Back up before and after. File ▸ Back Up RiskOS… writes the whole register to a single file, and RiskOS names it with the date, so the position you reported from stays beside the report.
  • Note what the board decided. Record accepted risks, revised appetites and new actions the same day, while you still remember which risk each comment was about.

Frequently asked questions

What should a board risk report include?

A cover, an executive summary, the risk matrix, a short list of top risks and the open actions. That is five sections and around ten pages. Controls, framework coverage, indicators and events suit a committee pack, and the full register belongs in an appendix if the pack is circulated in advance.

How many risks should a board report show?

Five to ten. The top risks section in RiskOS accepts any number from 3 to 50, so the choice is yours, but a shortlist stops being a shortlist somewhere past ten. Keep the number the same every quarter, and which risks enter and leave the list becomes useful information on its own.

How do I put my organisation's logo on a risk report?

Choose Set Up Branding in the report builder. It holds your business name, tagline, address, phone, email, website and a registration or VAT line, plus a logo in PNG, JPEG, PDF or SVG and an optional variant for dark backgrounds. The live preview is the real header and footer, so what you see is what exports and prints.

Can I send a board report someone can open without installing anything?

Yes. Export the report as HTML with ⇧⌘E and you get one self-contained file that opens in any browser, with no scripts and nothing loaded from the internet. It comes from the same snapshot as the PDF, so the two cannot disagree, and a director reading on a tablet gets the same figures as the board pack.

What is the difference between the executive summary and top risks?

The summary describes the register as a whole: how many risks are active, where they sit on average, how many are above appetite or overdue for review. Top risks names individual rows, worst first, with their owners and scores. The first tells a board how worried to be; the second tells it what to talk about.

Will the report change if I edit a risk afterwards?

No. Each export is a snapshot of the register at the moment you made it, which is what allows a figure to be quoted in minutes months later. Editing a risk afterwards changes the register, not the file you already sent. Export again once the register has settled if the board needs the newer position.

How often should a board risk report be produced?

Usually once a quarter, matched to the board calendar, with the register reviewed shortly before each export. Set a review cadence on each risk so that the ones due are surfaced for you, and run a review pass in the week before the meeting. Reports built from a current register need very little preparation.

Does building a board report send anything off my Mac?

No. Everything happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine except in the files you export yourself and choose to send. The report is assembled locally and saved wherever you point it, and no part of it passes through a server on the way.